High Threat Security Alert (A22-03-04): Multiple Vulnerabilities in Firefox
07 March 2022
Mozilla has published the advisory (MFSA2022-09) to address multiple vulnerabilities in Firefox browser. A remote attacker could entice a user running a vulnerable browser to visit a web page with specially crafted content to exploit the vulnerabilities.
Reports indicate that the vulnerabilities (CVE-2022-26485 and CVE-2022-26486) are being exploited in the wild. Users are advised to take immediate action to patch the affected systems to mitigate the elevated risk of cyber attacks.
Firefox Windows versions prior to version 97.0.2
Firefox ESR Windows versions prior to version 91.6.1
Successful exploitation of the vulnerabilities could lead to remote code execution or security restriction bypass on an affected system.
Mozilla has released new versions of the product to address the issues and they can be downloaded at the following URLs:
Firefox 97.0.2 for Windows https://www.mozilla.org/en-US/firefox/all/#product-desktop-release
Firefox ESR 91.6.1 for Windows https://www.mozilla.org/en-US/firefox/all/#product-desktop-esr
Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.